Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DDoS configuration

I have created the DDoS signatures in IP, IPS Policies.

I have followed the guide (https://community.sophos.com/kb/en-us/123182), but the last line reads - Navigate to Firewall and apply the Intrusion Prevention policy to the User/Network Rule.

My question is, what User / Network Policy?



This thread was automatically locked due to age.
Parents Reply Children
  • Thanks for your reply - I know where to find it (Advanced, Intrusion Prevention), it was which rule to apply to.

    So, I have two inbound rules, one for SMTP and one for HTTPS. I apply this IPS policy to both these rules and every other inbound rule that I create?

  • Paul,

    IPS is resource consuming so pay attention of which signature you add into each IPS profile. Be selective as much as you can. So in this case if you have one firewall rule where SMTP server/client is to be protected, create an IPS Profile where you include only SMTP protection (SMTP server attacks or Client mail attacks) and then create another IPS Profile where you add signature only for the web server you have (IIS, Apache) and so on.

    Regards